7.2 Use Cases: Triage

Updated 2 months ago by TruSTAR

Goals

  • Automatically run user-reported emails through Intelligence Pipeline.
  • Automatically prioritize events based on normalized scores. 
  • Streamline actions by connecting indicators and events with detection, IR, or orchestration tools. 

The graphic below illustrates how triage works using the optional TruSTAR Phishing Triage feature.

Workflow

  • Sources: Send internal event data to TruSTAR and use your Intelligence sources to normalize, score, and prioritize
  • Transformations: Prepare and prioritize events based on normalized scores.
  • Destinations: Connect indicators and events with detection, IR, or orchestration tools to streamline defensive actions.

Related Links


How Did We Do?